25

GitHub introduces staged publishing and new install-time controls for NPM

Nice…maybe will help some of the recent attacks

2 hours agokoinedad

If maintainers actually use it

40 minutes agoturkeyboi

This is the biggest question I also had after reading the blog post. Given the recent chain of attacks, wouldn't it make sense to enforce staged publish by default or at least gradually move over to it?